Trojan

TrojanDownloader:Win32/Upatre!pz removal instruction

Malware Removal

The TrojanDownloader:Win32/Upatre!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Upatre!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine TrojanDownloader:Win32/Upatre!pz?


File Info:

name: 0E9F1B04F4DCD11A7A59.mlw
path: /opt/CAPEv2/storage/binaries/733109bd3eeb030fcc968bb2326ad289bf50f23fcc53f326d58c9d640b9e6dae
crc32: DA7D8FA5
md5: 0e9f1b04f4dcd11a7a59371cbd3dffb2
sha1: ea52281083d9a4b75d87b7733937f95d305fa2d9
sha256: 733109bd3eeb030fcc968bb2326ad289bf50f23fcc53f326d58c9d640b9e6dae
sha512: 51f535f98f73c090e74e4e7d251b66afbee34a0dac3c2c0f6a6cd730916882de59644b13496c6a75f7fdc04e97eeb0700133eecc623ce098a3e90e55cd08b2f9
ssdeep: 384:TgEaziQIBt8yguzjEBNQiviL//U8zYpDc7+57ERkhNAdrHzd2U:T7a/6BlSvW//pzW7QBkU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T122B3E8F23FD99B3EF33FDEB589F580CAA83474115C42941D6094864B0863696DDFCA1A
sha3_384: 98e9922e1a4090f8a996622f05d11bcd04e59598b396f64d968dd8dd9adb86246087b15e9abd6353a2a5d149ad5729c0
ep_bytes: 837c24120ae8b6ffffff29d101c1e889
timestamp: 2004-05-28 09:53:59

Version Info:

0: [No Data]

TrojanDownloader:Win32/Upatre!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Delf.4!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Fugrafa.251293
FireEyeGeneric.mg.0e9f1b04f4dcd11a
CAT-QuickHealTrojan.Upatre.ZZ4
SkyhighBehavesLike.Win32.Infected.cz
ALYacGen:Variant.Fugrafa.251293
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Fugrafa.251293
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0052964f1 )
BitDefenderGen:Variant.Fugrafa.251293
K7GWTrojan ( 0052964f1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.36792.hmY@aebg6tni
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDownloader.Waski.B
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Dropper.Upatre-9944336-0
KasperskyHEUR:Trojan.Win32.Delf.gen
AlibabaTrojanDownloader:Win32/Upatre.f7b634a2
NANO-AntivirusTrojan.Win32.Vundo.fncedi
RisingDownloader.Upatre!8.B5 (TFE:5:nWFyk4X9xiM)
SophosTroj/Zbot-HMB
BaiduWin32.Trojan-Downloader.Waski.a
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.DownLoader9.19947
ZillyaDownloader.Upatre.Win32.70481
TrendMicroTROJ_UPATRE.SM5
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Fugrafa.251293 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.Zbot.fqcv
VaristW32/Upatre.NM.gen!Eldorado
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.Bublik
Kingsoftmalware.kb.a.1000
MicrosoftTrojanDownloader:Win32/Upatre!pz
XcitiumTrojWare.Win32.TrojanDownloader.Waski.B@80t362
ArcabitTrojan.Fugrafa.D3D59D
SUPERAntiSpywareTrojan.Agent/Gen-DownloaderUpatre
ZoneAlarmHEUR:Trojan.Win32.Delf.gen
GDataWin32.Trojan-Downloader.Upatre.BJ
GoogleDetected
AhnLab-V3Trojan/Win.Upatre.R477425
Acronissuspicious
McAfeePWSZbot-FMO!0E9F1B04F4DC
MAXmalware (ai score=88)
DeepInstinctMALICIOUS
VBA32TrojanDownloader.Upatre
Cylanceunsafe
PandaTrj/Genetic.gen
ZonerTrojan.Win32.21026
TrendMicro-HouseCallTROJ_UPATRE.SM5
TencentTrojan.Win32.Delf.wd
YandexTrojan.GenAsa!G7HTEQf3zWI
IkarusTrojan-Spy.Zbot
MaxSecureTrojan.Upatre.Gen
FortinetW32/Kryptik.CF!tr
AVGWin32:Waski-B [Cryp]
Cybereasonmalicious.083d9a
AvastWin32:Waski-B [Cryp]

How to remove TrojanDownloader:Win32/Upatre!pz?

TrojanDownloader:Win32/Upatre!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment